ANS-C01 exam dumps

ANS-C01 practice question 224 of 513

AWS Certified Advanced Networking - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

ANS-C01 Question 224

Single answer

An organization has set up a multi-account architecture using AWS Organizations. The central IT account is managing shared resources such as an AWS Transit Gateway for interconnecting VPCs across multiple accounts. To allow other member accounts within the organization to use this Transit Gateway, what should the central IT account do?

  1. A

    Share the Transit Gateway with member accounts using AWS Resource Access Manager (AWS RAM).

  2. B

    Create a peering connection from each member account's VPC to the central IT account's VPC.

  3. C

    Set up cross-account IAM roles in each member account and manually configure the Transit Gateway in those accounts.

  4. D

    Enable Service Control Policies (SCPs) in the AWS Organization to automatically share the Transit Gateway.

Show answer and explanation

Correct answer: A

Explanation

The correct approach to share a Transit Gateway with other accounts in an AWS Organization is to use AWS Resource Access Manager (AWS RAM). AWS RAM allows the central IT account to share resources (such as Transit Gateways) with other member accounts or organizational units without the need for manual configurations or additional permissions. This ensures centralized management and efficient resource sharing for multi-account architectures.

  • A. Correct.

    Correct. AWS Resource Access Manager (AWS RAM) allows you to share resources like Transit Gateways with other AWS accounts or Organizational Units (OUs) within an AWS Organization.

  • B. Incorrect.

    Incorrect. While VPC peering can connect two VPCs, it cannot provide the centralized connectivity and scalability that a Transit Gateway offers. Additionally, this option does not address the sharing of the Transit Gateway itself.

  • C. Incorrect.

    Incorrect. Cross-account IAM roles are used for granting permissions to access resources but do not facilitate the sharing of a Transit Gateway. This would require significant manual configuration and is not the appropriate solution.

  • D. Incorrect.

    Incorrect. Service Control Policies (SCPs) are used to manage permissions and restrict actions across an AWS Organization. They cannot be used to share resources like a Transit Gateway.

Timed practice exam

Take a ANS-C01 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam